{"_id":"@achasoft/dsh-advanced-sidebar","_rev":"2-6c1df3fc488162baa9749cbc9a6e6b39","name":"@achasoft/dsh-advanced-sidebar","dist-tags":{"latest":"0.3.0"},"versions":{"0.1.0":{"name":"@achasoft/dsh-advanced-sidebar","version":"0.1.0","keywords":["deepseek-harness","dsh","dsh-plugin","sidebar","git","terminal","file-browser","background-tasks","cordis"],"license":"MIT","_id":"@achasoft/dsh-advanced-sidebar@0.1.0","maintainers":[{"name":"navid.kianfar","email":"navid.kianfar@outlook.com"}],"homepage":"https://github.com/navid-kianfar/dsh-advanced-sidebar#readme","bugs":{"url":"https://github.com/navid-kianfar/dsh-advanced-sidebar/issues"},"dsh":{"bundle":{"patch":"./cordis.patch.yml"},"client":{"inject":["@deepseek-ai/dsh-api-remotes","@deepseek-ai/dsh-client-locale","@deepseek-ai/dsh-client-ui-conversation","@deepseek-ai/dsh-client-ui-layout","@deepseek-ai/dsh-client-ui-settings","@deepseek-ai/dsh-client-ui-settings-plugins"],"platform":"web"}},"dist":{"shasum":"20301a5e1cdfc5073e72f0eebc53649d22f1f39e","tarball":"https://registry.npmjs.org/@achasoft/dsh-advanced-sidebar/-/dsh-advanced-sidebar-0.1.0.tgz","fileCount":58,"integrity":"sha512-jJBxJR89Uu/AAfZflGrkodmheQCiv9Iv+IIA37fUgCI4vA4rOgCt1jRLj3p4pZD91OgZslJtLW241SCL/3tNJg==","signatures":[{"sig":"MEUCIQDk8YIGPh7nn0+VtnBUAl7isptViuuXYle0KQlhvevJIgIgb1EJsLI/IMu95c/waLz779OGI/jnwF9xKwSpTZHvE/c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":3367919},"main":"lib/index.js","type":"module","types":"./types/index.d.ts","engines":{"node":"^22.19 || >=24"},"exports":{".":{"types":"./types/index.d.ts","default":"./lib/index.js"},"./host":{"types":"./types/host/index.d.ts","default":"./lib/host.js"},"./client":{"default":"./lib/client.js"},"./remote":{"default":"./lib/remote.js"},"./typert":{"default":"./lib/typert.host.js"},"./package.json":"./package.json","./cordis.patch.yml":"./cordis.patch.yml"},"gitHead":"29c6ebd1a623ce7aa05a9e392766c3e4a84e7f6c","scripts":{"test":"node scripts/check-typert.mjs && vitest run","build":"tsc -p tsconfig.build.json && tsdown","prepare":"tsc -p tsconfig.build.json && tsdown","typecheck":"tsc --noEmit","check:typert":"node scripts/check-typert.mjs","regen:typert":"node scripts/emit-typert.mjs"},"_npmUser":{"name":"navid.kianfar","email":"navid.kianfar@outlook.com"},"repository":{"url":"git+https://github.com/navid-kianfar/dsh-advanced-sidebar.git","type":"git"},"_npmVersion":"11.19.1","description":"Advanced sidebar operations for the DeepSeek Harness Web Client: git changes, multi-session terminals, a file browser, a dev-server preview, background tasks, Open in, Archive and Delete, in a resizable dock beside the conversation","directories":{},"_nodeVersion":"25.2.1","dependencies":{"zod":"^4.4.3","@xterm/xterm":"^6.0.0","@xterm/addon-fit":"^0.11.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"react":"^18.2.0","tsdown":"^0.15.6","vitest":"^3.2.7","typescript":"^5.9.2","@types/node":"^22.20.1","@types/react":"~18.3.1","lightningcss":"^1.30.1","@types/react-dom":"^18.3.7","@deepseek-ai/cordis":"link:../../deepseek-harness/vendor/cordis","@deepseek-ai/dsh-fs":"link:../../deepseek-harness/packages/fs/fs","@deepseek-ai/dsh-llm":"link:../../deepseek-harness/packages/llm/llm","@deepseek-ai/dsh-jobs":"link:../../deepseek-harness/packages/jobs/jobs","@deepseek-ai/dsh-agent":"link:../../deepseek-harness/packages/core/agent","@deepseek-ai/dsh-session":"link:../../deepseek-harness/packages/core/session","@deepseek-ai/schemastery":"link:../../deepseek-harness/vendor/schemastery","@deepseek-ai/dsh-settings":"link:../../deepseek-harness/packages/settings/settings","@deepseek-ai/dsh-workspace":"link:../../deepseek-harness/packages/workspace/workspace","@deepseek-ai/dsh-subprocess":"link:../../deepseek-harness/packages/subprocess/subprocess","@deepseek-ai/dsh-api-remotes":"link:../../deepseek-harness/packages/api/remotes","@deepseek-ai/dsh-client-locale":"link:../../deepseek-harness/packages/client/locale","@deepseek-ai/dsh-client-runtime":"link:../../deepseek-harness/packages/client/runtime","@deepseek-ai/dsh-client-ui-slots":"link:../../deepseek-harness/packages/client/ui-slots","@deepseek-ai/dsh-client-ui-theme":"link:../../deepseek-harness/packages/client/ui-theme","@deepseek-ai/dsh-typert-protocol":"link:../../deepseek-harness/packages/typert/protocol","@deepseek-ai/dsh-client-ui-layout":"link:../../deepseek-harness/packages/client/ui-layout","@deepseek-ai/dsh-client-ui-sidebar":"link:../../deepseek-harness/packages/client/ui-sidebar","@deepseek-ai/dsh-client-ui-settings":"link:../../deepseek-harness/packages/client/ui-settings","@deepseek-ai/dsh-agent-default-model":"link:../../deepseek-harness/packages/core/agent-default-model","@deepseek-ai/dsh-session-persistence":"link:../../deepseek-harness/packages/session/session-persistence","@deepseek-ai/dsh-client-ui-primitives":"link:../../deepseek-harness/packages/client/ui-primitives","@deepseek-ai/dsh-client-ui-conversation":"link:../../deepseek-harness/packages/client/ui-conversation","@deepseek-ai/dsh-client-ui-settings-plugins":"link:../../deepseek-harness/packages/client/ui-settings-plugins"},"peerDependencies":{"@deepseek-ai/cordis":"*","@deepseek-ai/dsh-fs":"*","@deepseek-ai/dsh-llm":"*","@deepseek-ai/dsh-jobs":"*","@deepseek-ai/dsh-agent":"*","@deepseek-ai/dsh-session":"*","@deepseek-ai/schemastery":"*","@deepseek-ai/dsh-settings":"*","@deepseek-ai/dsh-workspace":"*","@deepseek-ai/dsh-subprocess":"*","@deepseek-ai/dsh-typert-protocol":"*","@deepseek-ai/dsh-agent-default-model":"*","@deepseek-ai/dsh-session-persistence":"*"},"_npmOperationalInternal":{"tmp":"tmp/dsh-advanced-sidebar_0.1.0_1788121764699_0.11235567587710782","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"_id":"@achasoft/dsh-advanced-sidebar@0.3.0","dsh":{"bundle":{"patch":"./cordis.patch.yml"},"client":{"inject":["@deepseek-ai/dsh-api-remotes","@deepseek-ai/dsh-client-locale","@deepseek-ai/dsh-client-ui-conversation","@deepseek-ai/dsh-client-ui-layout","@deepseek-ai/dsh-client-ui-settings","@deepseek-ai/dsh-client-ui-settings-plugins"],"platform":"web"}},"bugs":{"url":"https://github.com/navid-kianfar/dsh-advanced-sidebar/issues"},"dist":{"shasum":"90c2270a5ffc700f2fda6890bac1b48f8fb5e3ad","tarball":"https://registry.npmjs.org/@achasoft/dsh-advanced-sidebar/-/dsh-advanced-sidebar-0.3.0.tgz","fileCount":76,"integrity":"sha512-0VtX1NagxBgsI4YIgm4iMpfEIeP+obqBEoiDE49da8oDkRxBJpw/pWqsVM3GBrD9mARLem6a2reTr+A14H4yzg==","signatures":[{"sig":"MEQCIDnIWzrJ08d+8tnX5I85LFaDvSr5t1+XSvPQcEmdDKn1AiBUXjcnqAPMPCvI1qFqwRRWf5eZ5lPNQF25A7VaPo9E1Q==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICEJqj2Aa1mQWJA0AT+3XZI4ZFb3pZ2NfcJTmEGn+qYxAiBVizArpZ4nA7jFWMEDsnJO62MXFBdP4pG4V4+5rLrgdA=="}],"unpackedSize":3832588},"main":"lib/index.js","name":"@achasoft/dsh-advanced-sidebar","type":"module","types":"./types/index.d.ts","engines":{"node":"^22.19 || >=24"},"exports":{".":{"types":"./types/index.d.ts","default":"./lib/index.js"},"./host":{"types":"./types/host/index.d.ts","default":"./lib/host.js"},"./client":{"default":"./lib/client.js"},"./remote":{"default":"./lib/remote.js"},"./typert":{"default":"./lib/typert.host.js"},"./ui-preview":{"types":"./types/ui-preview.d.ts","default":"./lib/ui-preview.js"},"./package.json":"./package.json","./cordis.patch.yml":"./cordis.patch.yml"},"gitHead":"73eccc5e9301f87ac4f6cf8276e5f0c2652f31f7","license":"MIT","scripts":{"test":"node scripts/check-typert.mjs && vitest run","build":"tsc -p tsconfig.build.json && tsdown","prepare":"tsc -p tsconfig.build.json && tsdown","typecheck":"tsc --noEmit","check:typert":"node scripts/check-typert.mjs","regen:typert":"node scripts/emit-typert.mjs"},"version":"0.3.0","_npmUser":{"name":"navid.kianfar","email":"navid.kianfar@outlook.com"},"homepage":"https://github.com/navid-kianfar/dsh-advanced-sidebar#readme","keywords":["deepseek-harness","dsh","dsh-plugin","sidebar","git","terminal","file-browser","background-tasks","cordis"],"repository":{"url":"git+https://github.com/navid-kianfar/dsh-advanced-sidebar.git","type":"git"},"_npmVersion":"11.19.1","description":"Advanced sidebar operations for the DeepSeek Harness Web Client: git changes, multi-session terminals, a file browser, a dev-server preview, background tasks, Open in, Archive and Delete, in a resizable dock beside the conversation","directories":{},"maintainers":[{"name":"navid.kianfar","email":"navid.kianfar@outlook.com"}],"_nodeVersion":"25.2.1","dependencies":{"zod":"^4.4.3","@xterm/xterm":"^6.0.0","@xterm/addon-fit":"^0.11.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"react":"^18.2.0","tsdown":"^0.15.6","vitest":"^3.2.7","typescript":"^5.9.2","@types/node":"^22.20.1","@types/react":"~18.3.1","lightningcss":"^1.30.1","@types/react-dom":"^18.3.7","@deepseek-ai/cordis":"link:../../deepseek-harness/vendor/cordis","@deepseek-ai/dsh-fs":"link:../../deepseek-harness/packages/fs/fs","@deepseek-ai/dsh-llm":"link:../../deepseek-harness/packages/llm/llm","@deepseek-ai/dsh-jobs":"link:../../deepseek-harness/packages/jobs/jobs","@deepseek-ai/dsh-agent":"link:../../deepseek-harness/packages/core/agent","@deepseek-ai/dsh-tools":"link:../../deepseek-harness/packages/core/tools","@deepseek-ai/dsh-session":"link:../../deepseek-harness/packages/core/session","@deepseek-ai/schemastery":"link:../../deepseek-harness/vendor/schemastery","@deepseek-ai/dsh-settings":"link:../../deepseek-harness/packages/settings/settings","@deepseek-ai/dsh-workspace":"link:../../deepseek-harness/packages/workspace/workspace","@deepseek-ai/dsh-subprocess":"link:../../deepseek-harness/packages/subprocess/subprocess","@deepseek-ai/dsh-api-remotes":"link:../../deepseek-harness/packages/api/remotes","@deepseek-ai/dsh-client-locale":"link:../../deepseek-harness/packages/client/locale","@deepseek-ai/dsh-client-runtime":"link:../../deepseek-harness/packages/client/runtime","@deepseek-ai/dsh-host-webserver":"link:../../deepseek-harness/packages/host/webserver","@deepseek-ai/dsh-client-ui-slots":"link:../../deepseek-harness/packages/client/ui-slots","@deepseek-ai/dsh-client-ui-theme":"link:../../deepseek-harness/packages/client/ui-theme","@deepseek-ai/dsh-typert-protocol":"link:../../deepseek-harness/packages/typert/protocol","@deepseek-ai/dsh-client-ui-layout":"link:../../deepseek-harness/packages/client/ui-layout","@deepseek-ai/dsh-client-ui-sidebar":"link:../../deepseek-harness/packages/client/ui-sidebar","@deepseek-ai/dsh-client-ui-settings":"link:../../deepseek-harness/packages/client/ui-settings","@deepseek-ai/dsh-agent-default-model":"link:../../deepseek-harness/packages/core/agent-default-model","@deepseek-ai/dsh-session-persistence":"link:../../deepseek-harness/packages/session/session-persistence","@deepseek-ai/dsh-client-ui-primitives":"link:../../deepseek-harness/packages/client/ui-primitives","@deepseek-ai/dsh-client-ui-conversation":"link:../../deepseek-harness/packages/client/ui-conversation","@deepseek-ai/dsh-client-ui-settings-plugins":"link:../../deepseek-harness/packages/client/ui-settings-plugins"},"peerDependencies":{"@deepseek-ai/cordis":"*","@deepseek-ai/dsh-fs":"*","@deepseek-ai/dsh-llm":"*","@deepseek-ai/dsh-jobs":"*","@deepseek-ai/dsh-agent":"*","@deepseek-ai/dsh-tools":"*","@deepseek-ai/dsh-session":"*","@deepseek-ai/schemastery":"*","@deepseek-ai/dsh-workspace":"*","@deepseek-ai/dsh-subprocess":"*","@deepseek-ai/dsh-typert-protocol":"*","@deepseek-ai/dsh-agent-default-model":"*","@deepseek-ai/dsh-session-persistence":"*"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/dsh-advanced-sidebar_0.3.0_1789537303132_0.7631741420735532"}}},"time":{"created":"2026-08-30T20:29:24.604Z","modified":"2026-09-16T05:41:43.428Z","0.1.0":"2026-08-30T20:29:24.873Z","0.3.0":"2026-09-16T05:41:43.245Z"},"bugs":{"url":"https://github.com/navid-kianfar/dsh-advanced-sidebar/issues"},"license":"MIT","homepage":"https://github.com/navid-kianfar/dsh-advanced-sidebar#readme","keywords":["deepseek-harness","dsh","dsh-plugin","sidebar","git","terminal","file-browser","background-tasks","cordis"],"repository":{"url":"git+https://github.com/navid-kianfar/dsh-advanced-sidebar.git","type":"git"},"description":"Advanced sidebar operations for the DeepSeek Harness Web Client: git changes, multi-session terminals, a file browser, a dev-server preview, background tasks, Open in, Archive and Delete, in a resizable dock beside the conversation","maintainers":[{"name":"navid.kianfar","email":"navid.kianfar@outlook.com"}],"readme":"# @achasoft/dsh-advanced-sidebar\n\nA session menu and a resizable side dock for the [DeepSeek Harness](https://github.com/deepseek-ai/deepseek-harness) (dsh) Web Client. The **⋯** menu in the session header opens these panels in a column to the right of the conversation:\n\n- **Changes**: git status, diffs, staging, commit, a model-written commit message, and push;\n- **Terminal**: your own shells, in tabs;\n- **Files**: a file browser with text preview;\n- **Preview**: dev servers, workspace files, URLs, or a scratchpad;\n- **Background tasks**: the session's jobs.\n\nThe same menu has **Open in**, **Download session log**, **Archive**, and **Delete**. Work the browser cannot do itself (running git, opening a pseudo-terminal, launching an editor) runs on the host through this plugin's own RPC namespace. One optional model tool, `ui_preview`, lets the agent inspect and drive the Preview panel.\n\n![The dock open beside the conversation, showing the Changes panel with staged and unstaged files, a diff, and the commit box](https://raw.githubusercontent.com/navid-kianfar/dsh-advanced-sidebar/main/docs/screenshots/dock-changes.png)\n\n## Features\n\n### Session menu\n\nA **⋯** button in the open session's header. It acts on that session, using the session's own working directory, or its workspace path when the session has none.\n\n| Entry | What it does |\n| --- | --- |\n| Changes, Terminal, Files, Preview, Background tasks | Opens that panel in the dock. The open panel's entry has a check mark, and choosing it again closes the dock. |\n| Open in ▸ | **New window** (a second tab of the Web Client), each configured editor, and the OS file manager: Finder, File Explorer, or `xdg-open` on Linux. |\n| Download session log | Exports the session as a ZIP through the harness's own exporter. See the note below. |\n| Archive | Hides the session. Its log stays on disk. |\n| Delete | Asks for confirmation, then archives. See [Known limitations](#known-limitations). |\n\nWhen the host cannot serve an entry (git not installed, an editor command not found, no subprocess capability), the entry stays in the menu, disabled, with the reason next to it. An entry switched off in settings is not shown at all. The menu asks the host again each time it opens, so installing git or an editor shows up without a restart.\n\n**Download session log.** The harness package `@deepseek-ai/dsh-session-log-export` adds its own **⋯** button, with that single entry, to the same header row. This plugin hides that button: it registers an entry with the same id (`session-log-download`) at priority `-1`, and moves the entry into its own menu. Exporting still uses the harness's controller and dialog, so `/export` keeps working. If the harness package is absent or its controller has a different shape, nothing is hidden and the menu has no Download entry.\n\n![Session header ⋯ menu open: the panel entries, the Open in submenu, Download session log, Archive, and Delete](https://raw.githubusercontent.com/navid-kianfar/dsh-advanced-sidebar/main/docs/screenshots/session-menu.png)\n\n### The dock\n\nPanels open in a column on the right of the app frame. The conversation narrows to make room, so the dock does not cover it.\n\n- **Resizing.** Drag the left edge, use Left and Right on the focused handle, or double-click the handle to return to the configured width.\n- **Width limits.** The width is kept between 280 px and 960 px, and never leaves the conversation less than 400 px.\n- **Narrow windows.** When even the minimum width would squeeze the conversation below 400 px, the dock floats over the conversation instead.\n\n### Changes\n\n- **Status.** The working directory's status, grouped as Staged, Not staged, Untracked, and Conflicted, with branch, ahead, and behind counts. Click a file to see its patch, with **Copy patch**.\n- **Staging.** **Stage** / **Unstage** a file, or a whole group with **Stage all** / **Unstage all**.\n- **Commit.** **Commit** records what is staged, with an optional **Amend the previous commit**. The author git would record (`git var GIT_AUTHOR_IDENT`) is shown under the message box, so a missing `user.email` is visible before you commit.\n- **Generate.** Writes a commit message with the model the composer is currently set to. The model sees only the staged patch, up to `commitMessageMaxBytes`. The message goes into the box for you to edit, and nothing is committed automatically.\n- **Push.** Pushes the current branch to its upstream (`git push` with no arguments). A branch with no upstream shows **Publish** instead, which pushes to `origin`, or to the first remote if there is no `origin`, and sets the upstream. Force push, a remote picker, and custom refspecs are not offered.\n- **No discard.** There is no way to discard changes from this panel. Use the Terminal panel.\n\n### Terminal\n\n- **Your own shells.** Interactive shells in the session's working directory, in tabs, up to `maxTerminals`. They are separate from the model's terminals.\n- **Controls.** **Interrupt** and Ctrl+C send SIGINT to the foreground process group. **Clear** clears the screen, and **Restart** starts a new shell.\n- **Shells keep running.** Closing the dock or switching panels leaves them running. Reopening a tab replays the output the host kept (`terminalScrollback`). Closing a tab ends its shell, and so does archiving or deleting the session.\n- **Emulator.** The screen is `@xterm/xterm`, so colors, line editing, and full-screen programs work.\n\n![Terminal panel with two shell tabs and git command output](https://raw.githubusercontent.com/navid-kianfar/dsh-advanced-sidebar/main/docs/screenshots/terminal-panel.png)\n\n### Files\n\n- **Browsing.** The working directory, one level at a time. Hidden entries are excluded unless `filesShowHidden` is on.\n- **Preview.** A text preview up to `filesMaxPreviewBytes`. Binary files show their size.\n- **Actions.** **Open with the default application** and **Show in file manager**.\n\n![Files panel listing a directory, with a text file previewed](https://raw.githubusercontent.com/navid-kianfar/dsh-advanced-sidebar/main/docs/screenshots/files-panel.png)\n\n### Preview\n\nFour modes, with a viewport picker (Desktop, Tablet, Mobile, Custom) in every mode.\n\n| Mode | What it shows |\n| --- | --- |\n| **Server** | Launch configurations from the workspace's `.claude/launch.json` (Claude Code's format) and the `previews` setting. The file wins when both define the same name. **Start** and **Stop** a server, view **Logs** (these open automatically when a start fails), **Open in a new window**, or **Open inspectable**, which hands the URL to URL mode. |\n| **File** | A workspace file, rendered by type: HTML and SVG in a frame, Markdown rendered, images, audio, video, PDF, and plain text. The panel reloads when the file changes. Files over `previewMaxFileBytes`, or of unknown types, offer **Open with the default application**. |\n| **URL** | Any `http(s)` address. A `localhost`, `127.x.x.x`, or `[::1]` address is loaded through the host's proxy, so the frame is same-origin and its DOM and console can be read. Other addresses are framed directly and labeled cross-origin. |\n| **Scratchpad** | HTML you type, rendered from a host route. The text is saved per workspace in this browser's `localStorage`. |\n\nFor a launch configuration, readiness means the configured `port` accepts a TCP connection, checked until `previewReadyTimeoutMs`. The child process gets `PORT`, `NO_COLOR=1`, and `FORCE_COLOR=0`. Stopping sends SIGTERM to the process tree, then SIGKILL after `previewGraceMs`.\n\n`.claude/launch.json` example:\n\n```json\n{\n  \"version\": \"0.0.1\",\n  \"configurations\": [\n    { \"name\": \"web\", \"runtimeExecutable\": \"npm\", \"runtimeArgs\": [\"run\", \"dev\"], \"port\": 3000 }\n  ]\n}\n```\n\n![Preview panel in Server mode running a launch configuration, with the proxied page and the viewport picker](https://raw.githubusercontent.com/navid-kianfar/dsh-advanced-sidebar/main/docs/screenshots/preview-panel.png)\n\n### Background tasks\n\n- **List.** The session's background jobs, filtered by text, status, and start date, with duration and status.\n- **Stop.** Requires `allowTaskKill`. Stopping a task also suppresses the completion notice the model would otherwise receive.\n- **Output.** Requires `showTaskOutput`, and appears only after the task has finished and its completion has been reported. Reading output earlier would consume the output the model reads.\n\n### Settings card\n\n**Settings → Plugins → Advanced sidebar** edits most settings and shows, for each Open in target and preview configuration, whether it is available on this host. See [Configuration](#configuration).\n\n![Advanced sidebar settings card, expanded, with menu entry toggles, limits, and the Open in target list](https://raw.githubusercontent.com/navid-kianfar/dsh-advanced-sidebar/main/docs/screenshots/settings.png)\n\n## Requirements\n\n- **DeepSeek Harness 0.1.5-rc.2** with the `web` profile. This is the version the plugin is tested against. Node `^22.19 || >=24`.\n- **pnpm** on `PATH`, because `dsh plugin` runs pnpm.\n- **git 2.23 or newer** on the host `PATH` for Changes, because unstaging uses `git restore --staged`.\n- Harness capabilities, each optional. A missing one disables only the entries that need it, with the reason shown:\n\n| Capability | Needed by |\n| --- | --- |\n| `subprocess` | Changes, Terminal, Preview servers, Open in |\n| `fs` | Changes, Terminal, Files, Preview |\n| `jobs` | Background tasks (Stop and Output) |\n| `workspaceRegistry` | Delete; Preview File mode (files are served only from registered workspaces) |\n| `llm` + `agentDefaultModel` | **Generate** commit message |\n| `connection` (with `requestRejection`) + `webServer` | Preview's same-origin routes: File mode, the loopback proxy, Scratchpad |\n| `tools` | The `ui_preview` model tool |\n| `sessionLogDownload` (from `@deepseek-ai/dsh-session-log-export`) | Download session log |\n\n- **OS:** developed and tested on macOS. The code has Windows and Linux branches (shell fallback, file-manager command) that are not verified.\n\n## Install\n\n```bash\ndsh plugin --profile web add @achasoft/dsh-advanced-sidebar\ndsh web\n```\n\n`dsh plugin --profile <name> …` runs pnpm with the remaining arguments in `$DSH_HOME/profiles/<name>` (default `~/.dsh/profiles/web`). Afterwards, dsh adds every dependency whose `package.json` declares `dsh.bundle` to `dsh.profile.bundles`. This package declares `\"dsh\": { \"bundle\": { \"patch\": \"./cordis.patch.yml\" } }`, so it is enabled with no manual edit. Restart `dsh web` after installing.\n\nTo uninstall, remove the package. dsh also drops it from `dsh.profile.bundles`:\n\n```bash\ndsh plugin --profile web remove @achasoft/dsh-advanced-sidebar\n```\n\n### How `cordis.patch.yml` is applied\n\nAt boot, dsh builds the configuration from patch layers, in this order:\n\n1. Each bundle's `cordis.patch.yml`, in `dsh.profile.bundles` order.\n2. `$DSH_HOME/profiles/<name>/cordis.patch.yml`.\n3. `$DSH_HOME/cordis.patch.yml`.\n4. Any `--patch <file>` overlays.\n\nLater layers override earlier ones by row `id`. This package inserts three rows:\n\n| id | name | Role |\n| --- | --- | --- |\n| `advanced-sidebar` | `@achasoft/dsh-advanced-sidebar/host` | Host service, RPC namespace `advancedSidebar`, the `advanced-sidebar` settings section, and the preview routes. |\n| `advanced-sidebar-ui` | `@achasoft/dsh-advanced-sidebar` | Browser half. It must be the bare package name, because the Web Client finds browser code by resolving `<row name>/package.json`. |\n| `advanced-sidebar-ui-preview` | `@achasoft/dsh-advanced-sidebar/ui-preview` | The `ui_preview` model tool. |\n\nTo keep the sidebar but not give the model a tool, disable the third row in your profile's `cordis.patch.yml`:\n\n```yaml\n- id: advanced-sidebar-ui-preview\n  disabled: true\n```\n\nTo see the composed result:\n\n```bash\ndsh --profile web --dump-config\n```\n\n## Configuration\n\nAll keys below are in the `config` of the `advanced-sidebar` row. A patch replaces a row's whole `config`, so an override must restate every key. Copy the row from this package's `cordis.patch.yml` and edit it.\n\nThe host schema declares no defaults, and every key except `commitMessagePrompt` and `terminalShell` is required. The defaults listed are the values `cordis.patch.yml` ships. Changes saved from the settings card are stored as a user layer over the patch value. **Card** marks keys the card can edit. On a Web Client that is not on loopback the harness settings scope is unavailable, so the card and menu show the host's values read-only.\n\n**Menu and behavior**\n\n| Key | Default | Card | What it does |\n| --- | --- | --- | --- |\n| `showInSessionHeader` | `true` | yes | Shows the ⋯ menu in the session header. When off, the button still appears if needed to offer Download session log, and nothing else. |\n| `showChanges`, `showTerminal`, `showFiles`, `showTasks`, `showPreview`, `showOpenIn`, `showArchive` | `true` | yes | Shows each menu entry. |\n| `showDelete` | `true` | yes | Shows Delete. When off, the host also refuses `deleteSession`. |\n| `panelWidth` | `460` | yes | Dock width in px (schema allows 280–1400; the dock uses at most 960). Dragging the edge saves here when the scope is writable. |\n| `deleteMode` | `archive` | yes | `archive` or `purge`. `purge` is unavailable on this harness; see limitations. |\n| `confirmDelete` | `true` | yes | Asks before Delete. Must be `true` when `deleteMode` is `purge`. |\n| `allowTaskKill` | `true` | yes | Offers Stop, enforced by the host. |\n| `showTaskOutput` | `true` | yes | Offers Output for finished tasks, enforced by the host. |\n\n**git (Changes panel)**\n\n| Key | Default | Card | What it does |\n| --- | --- | --- | --- |\n| `gitMaxFiles` | `500` | yes | Most files in one status reading. |\n| `gitDiffMaxBytes` | `262144` | no | Largest patch returned for one file. |\n| `gitTimeoutMs` | `20000` | yes | Time limit for each read-only git command. |\n| `allowGitStaging` | `true` | yes | Stage and unstage, enforced by the host. |\n| `allowGitCommit` | `true` | yes | Commit, enforced by the host. Also requires staging. |\n| `gitCommitTimeoutMs` | `120000` | yes | Time limit for `git commit`, which runs hooks. |\n| `allowGitPush` | `true` | yes | Push and Publish, enforced by the host. |\n| `gitPushTimeoutMs` | `180000` | yes | Time limit for a push. |\n| `allowCommitMessageDraft` | `true` | yes | **Generate**, enforced by the host. Also requires commit. |\n| `commitMessagePrompt` | `''` | no | Replaces the built-in commit-message instruction. Empty uses the built-in one. |\n| `commitMessageMaxBytes` | `65536` | yes | Largest staged patch sent to the model. A longer patch is truncated, and the model is told it was cut. |\n\n**Terminal and Files**\n\n| Key | Default | Card | What it does |\n| --- | --- | --- | --- |\n| `terminalShell` | `''` | yes | Shell to run. Empty uses `$SHELL`, then `/bin/sh` (`%COMSPEC%` or `powershell.exe` on Windows). |\n| `terminalScrollback` | `200000` | no | Characters of output kept per terminal for replay. |\n| `maxTerminals` | `4` | yes | Most panel terminals open at once (1–32). |\n| `terminalGraceMs` | `3000` | no | Delay between TERM and KILL when a terminal closes. |\n| `filesMaxPreviewBytes` | `262144` | no | Largest file shown in the Files preview. |\n| `filesMaxEntries` | `2000` | no | Most entries listed per directory. |\n| `filesShowHidden` | `false` | no | Lists dot-files. |\n\n**Preview**\n\n| Key | Default | Card | What it does |\n| --- | --- | --- | --- |\n| `previewsFromLaunchFile` | `true` | yes | Reads `.claude/launch.json`. |\n| `previews` | `[]` | no (listed) | Extra launch rows: `name`, `runtimeExecutable`, `runtimeArgs`, `port`, `url`, `cwd`. An empty `runtimeExecutable` makes the row attach-only: it points the frame at `url` and starts nothing. |\n| `maxPreviews` | `3` | yes | Most dev servers running at once. |\n| `previewReadyTimeoutMs` | `60000` | yes | How long to wait for the port to accept connections. |\n| `previewScrollback` | `200000` | no | Log characters kept per server. |\n| `previewGraceMs` | `3000` | no | Delay between TERM and KILL when a server stops. |\n| `previewMaxFileBytes` | `33554432` | no | Largest workspace file served to the frame. |\n| `previewProxyTimeoutMs` | `30000` | no | Time limit for one proxied request to a loopback server. |\n| `previewCommandTimeoutMs` | `15000` | no | How long a `ui_preview` command other than `open` waits for the panel. |\n| `previewBindTtlMs` | `6000` | no | How long a panel counts as open after its last poll. |\n\n**Open in**\n\n| Key | Default | Card | What it does |\n| --- | --- | --- | --- |\n| `editors` | VS Code (`code`), Cursor (`cursor`), Zed (`zed`) | no (availability listed) | Rows of `id`, `label`, `command`, `args`. `args` go before the path. `id` must match `^[a-z][a-z0-9-]*$`, be unique, and not be `reveal`. |\n\nThe host refuses a configuration at load when:\n\n- an editor id is invalid or duplicated, or an editor command is empty;\n- a preview name is empty or duplicated;\n- a preview row has no command, no URL, and no port;\n- `deleteMode` is `purge` while `confirmDelete` is `false`.\n\nThe `advanced-sidebar-ui-preview` row has one key, `commandTimeoutMs` (default `15000`, range 1000–600000). It is the default wait for `ui_preview open` when the call passes no `waitMs`.\n\n## Model tool and RPC\n\n### `ui_preview`\n\nRegistered only when the `advanced-sidebar-ui-preview` row is composed. It works only while the Preview panel is open in the same session. Otherwise it returns immediately with a message telling the model to open the panel.\n\n| Action | Arguments | Result |\n| --- | --- | --- |\n| `open` | `url` or `path`; optional `workspace`, `waitMs` | Points the panel at an http(s) URL or a workspace file, and reports whether the page can be inspected. |\n| `dom` | optional `selector` | The rendered DOM: tags, ids and classes, text, display, and box metrics, plus the page text, viewport, and URL. |\n| `eval` | `expression` | Runs JavaScript in the frame and returns the value as JSON. |\n| `console` | optional `cursor` | Console messages, uncaught errors, and unhandled rejections logged since `cursor`. |\n| `click` | `selector` | Dispatches `click()` on the element. |\n| `type` | `selector`, `text`, optional `key` | Sets the element's value, dispatches `input` and `change`, then optionally the key. |\n| `reload` | none | Reloads the frame. |\n| `resize` | `width`, `height` | Sets the frame viewport size. |\n| `close` | none | Closes the preview. |\n\n`dom`, `eval`, `click`, and `type` refuse a cross-origin frame by name instead of returning nothing.\n\n### RPC namespace `advancedSidebar`\n\nThe browser half calls these endpoints over the harness's client connection:\n\n- `describe`\n- `gitStatus`, `gitDiff`, `gitStage`, `gitUnstage`, `gitCommit`, `gitPush`, `gitCommitMessage`\n- `terminalOpen`, `terminalRead`, `terminalWrite`, `terminalSignal`, `terminalClose`\n- `listEntries`, `readFile`\n- `previewList`, `previewStart`, `previewStop`, `previewLogs`, `previewFileInfo`, `previewPoll`, `previewResult`, `previewRelease`\n- `openIn`\n- `taskKill`, `taskOutput`\n- `deleteSession`\n\nEvery endpoint returns a result value with a failure code instead of throwing. The root export re-exports the types.\n\n## Security notes\n\n- **git does not run programs the repository configures.**\n  - Every git command passes `-c core.fsmonitor=false`.\n  - Every `git diff` passes `--no-ext-diff --no-textconv`.\n  - Read-only commands (status, diff, log, identity, remote list) switch off `filter.<driver>.clean`/`process` from the repository's local and per-worktree config. Global and system filters, such as git-lfs, still run. A driver name that cannot be disabled this way, because it contains `=`, makes the reading fail instead.\n  - Stage, commit, and push are explicit user actions and keep git's normal behavior, including hooks and filters.\n- **No option injection.**\n  - Paths are checked to be inside the repository and passed after `--`.\n  - The commit message is a single `-m` argument.\n  - Publish checks the branch with `git check-ref-format --branch`, checks the remote as `refs/remotes/<remote>/HEAD`, and pushes `-- <remote> refs/heads/<b>:refs/heads/<b>`.\n  - Credential prompts are disabled (`GIT_TERMINAL_PROMPT=0`), so a push that needs credentials fails instead of hanging.\n- **Host-enforced switches.** `allowGitStaging`, `allowGitCommit`, `allowGitPush`, `allowCommitMessageDraft`, `allowTaskKill`, `showTaskOutput`, and `showDelete` are checked by the host, not only hidden in the UI.\n- **Paths stay inside the workspace.** Files, Preview File mode, and `ui_preview` file arguments are resolved through the harness filesystem's containment check, so symlinks cannot escape.\n- **Panel terminals are separate from the model's terminals.** They are allocated with `ctx.subprocess.spawnTerminal`, not the agent's terminal registry, so your keystrokes never reach a terminal the model controls.\n- **Preview routes are gated.** The routes `/advanced-sidebar/preview-file`, `/advanced-sidebar/preview-proxy` (plus its websocket upgrade), and `/advanced-sidebar/preview-scratchpad` each call the harness connection's `requestRejection` first. That is the same host/origin check and signed `dsh-auth-*` cookie check that guards `/api`, and it answers `401`/`403` otherwise. If the connection has no such gate, the routes are not registered at all.\n  - **Loopback only.** The proxy forwards only to literal loopback hosts (`localhost`, `127.0.0.0/8`, `[::1]`). A hostname that merely resolves to loopback is refused.\n  - **No credential forwarding.** The harness's `dsh-auth-*` cookie is stripped from forwarded requests and from upstream `Set-Cookie` headers.\n  - **Registered workspaces only.** The file route serves only files inside a workspace in `workspaceRegistry`.\n  - **Scratchpad size.** Scratchpad documents are limited to 1 MiB.\n  - **No caching.** Responses are sent with `no-store`.\n- **A proxied page runs as the Web Client's origin.** Its scripts can call the harness API with your session. Only preview dev servers you trust as much as a browser tab signed in to the harness.\n- **`ui_preview open` accepts any http(s) URL**, like the address bar. Only loopback URLs become same-origin and inspectable.\n\n## Known limitations\n\n- **Delete only archives.** The harness's session persistence API (0.1.5-rc.2) has no way to remove a session. So `deleteMode: purge` is reported unavailable, the card will not select it, and a configured `purge` archives and returns the reason the log was kept.\n- **No push channel.** An out-of-tree plugin cannot add wire frames, so terminal output, preview logs, and `ui_preview` commands are polled.\n  - The command poll runs every 600 ms while there is work and every 2 s when idle.\n  - A watched preview file is checked every 900 ms.\n  - Background tasks are the exception: they use the harness's existing `session/jobs` push.\n- **No terminal resize.** The subprocess API has no resize call. The emulator follows the dock, but the shell keeps its starting size until you **Restart** it.\n- **Server mode frames are cross-origin.** A started dev server's own URL is framed directly. Use **Open inspectable** to load it through the proxy.\n- **Websocket proxying works only at the proxy root.** A dev server that opens its live-reload socket on a subpath is not tunneled. The page still renders, and HTTP streaming (including SSE) is proxied.\n- **`ui_preview eval` runs as a function body.** Declarations do not persist between calls.\n- **Console capture sees only the page's `console` and error events**, not network failures or workers.\n- **Byte-range requests need `fs.readByteRange`.** Without it, the file route answers a full `200`, so media plays but cannot seek.\n- **The dock depends on the frame's DOM.** It reserves width by setting a CSS property and a data attribute on the `shell.overlay` frame element. A harness layout change could require an update.\n- **Large browser bundle.** The terminal emulator makes up most of it, and the harness serves one file per plugin, so it cannot be loaded lazily.\n- **Generate costs model tokens.** Each press calls the deployment's provider. Set `allowCommitMessageDraft: false` to remove it.\n- **Stopping a task hides its completion from the model.** Set `allowTaskKill: false` to remove Stop.\n\n## Development\n\nThe dev dependencies are `link:` specifiers to a DeepSeek Harness source checkout at `../../deepseek-harness`, relative to this directory. Clone the harness there before installing.\n\n```bash\npnpm install\npnpm run typecheck\npnpm test              # checks generated/ against src/host, then runs vitest\npnpm run build         # tsc -p tsconfig.build.json, then tsdown -> lib/\n```\n\n`generated/` is the committed Typert RPC contract, written by `scripts/emit-typert.mjs` in the harness generator's format. If you change `src/host/types.ts` or the `@Remote` methods, update that script's spec and regenerate:\n\n```bash\npnpm run regen:typert  # rewrites generated/ and its fingerprint\npnpm run check:typert  # the same check pnpm test runs first\n```\n\nTo load your checkout into a local profile, build it, then add it by path:\n\n```bash\npnpm run build\ndsh plugin --profile web add \"$(pwd)\"\ndsh web\n```\n\nThe profile loads the built `lib/` output, so build first. After changing browser code, rebuild and reload the page. After changing anything under `src/host/`, or regenerating `generated/`, restart `dsh web`.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}